XSS when attaching a file to an issue

XMLWordPrintable

    • 6.01
    • 6.5

      Hi,

      I found a persistent XSS vulnerability when attaching a file to an issue.
      The steps to reproduce are the following :

      • Attach a file to an issue. Its name must contain "<script>alert('XSS')</script>". I used a python script to do that.
      • Browse to the issue and open the ALL tab under activity. A popup should appear.

      See the attachment for the result.

        1. XSS.png
          31 kB
          Yohan Joubert

            Assignee:
            Roman Tekhov (Inactive)
            Reporter:
            Yohan Joubert
            Votes:
            0 Vote for this issue
            Watchers:
            6 Start watching this issue

              Created:
              Updated:
              Resolved: